Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-41702 | 1 Siberiancms | 1 Siberiancms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | |||||
| CVE-2024-41679 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 6.5 MEDIUM |
| GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17. | |||||
| CVE-2024-41618 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query. | |||||
| CVE-2024-41579 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability | |||||
| CVE-2024-41551 | 1 Campcodes | 1 Supplier Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= . | |||||
| CVE-2024-41550 | 1 Campcodes | 1 Supplier Management System | 2026-06-17 | N/A | 7.2 HIGH |
| CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice_items.php?id= . | |||||
| CVE-2024-41512 | 1 4pace | 1 Cadclick | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter. | |||||
| CVE-2024-41444 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so. | |||||
| CVE-2024-41372 | 1 Organizr | 1 Organizr | 2026-06-17 | N/A | 9.8 CRITICAL |
| Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php. | |||||
| CVE-2024-41370 | 1 Organizr | 1 Organizr | 2026-06-17 | N/A | 9.8 CRITICAL |
| Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php. | |||||
| CVE-2024-41238 | 1 Lopalopa | 1 Responsive School Management System | 2026-06-17 | N/A | 5.3 MEDIUM |
| A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | |||||
| CVE-2024-41237 | 1 Lopalopa | 1 Responsive School Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | |||||
| CVE-2024-41236 | 1 Lopalopa | 1 Responsive School Management System | 2026-06-17 | N/A | 7.2 HIGH |
| A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page | |||||
| CVE-2024-40689 | 1 Ibm | 2 Infosphere Information Server, Infosphere Information Server On Cloud | 2026-06-17 | N/A | 6.0 MEDIUM |
| IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719. | |||||
| CVE-2024-40638 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 8.1 HIGH |
| GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17. | |||||
| CVE-2024-40637 | 1 Getdbt | 1 Dbt Core | 2026-06-17 | N/A | 4.2 MEDIUM |
| dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a user installs a package in dbt, it has the ability to override macros, materializations, and other core components of dbt. This is by design, as it allows packages to extend and customize dbt's functionality. However, this also means that a malicious package could potentially override these components with harmful code. This issue has been fixed in versions 1.8.0, 1.6.14 and 1.7.14. Users are advised to upgrade. There are no kn own workarounds for this vulnerability. Users updating to either 1.6.14 or 1.7.14 will need to set `flags.require_explicit_package_overrides_for_builtin_materializations: False` in their configuration in `dbt_project.yml`. | |||||
| CVE-2024-40614 | 1 Egroupware | 1 Egroupware | 2026-06-17 | N/A | 9.8 CRITICAL |
| EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting. | |||||
| CVE-2024-40570 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 6.5 MEDIUM |
| SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component. | |||||
| CVE-2024-40560 | 1 Project Team | 1 Tmall Demo | 2026-06-17 | N/A | 7.3 HIGH |
| Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability. | |||||
| CVE-2024-40542 | 1 Codermy | 1 My-springsecurity-plus | 2026-06-17 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/role?offset. | |||||
